Methods and apparatus to dynamically control connectivity within virtual private networks
Summary by NHIP
Dynamic VPN Route Server
The route server stores database indications defining additional connectivity between provider edge routers and modifies received border gateway protocol advertisements. It generates a copy of the advertisement and changes the first border gateway protocol route target attribute to match the stored additional connectivity before broadcasting the modified copy.
Claim Score by NHIP
Abstract
Methods and apparatus to dynamically control connectivity within VPNs are disclosed. A disclosed example route server to control connectivity within a VPN comprises a memory to implement a database, a border gateway protocol (BGP) engine to process BGP advertisements, a network interface to receive a first BGP advertisement, which a first route target (RT) associated with the first PE router, from a first provider edge (PE) router associated with the VPN, and an intra-VPN connectivity controller to, in response to the first BGP advertisement, query the database to determine whether the first PE router is to be communicatively coupled to a second PE router of the VPN and when the first and second PE routers of the VPN are to be communicatively coupled, direct the BGP engine to form a second BGP advertisement that includes a second RT associated with the second PE router based on the first BGP advertisement.

Term
3.3 yearsleft in the term
Expires 1 January 2030, including 427 days of term adjustment.
- Priority
- Filed
- Granted
- Today
- Expires
17 claims: 3 independent, 14 dependent
- 1A route server, comprising:a memory comprising machine readable instructions;and a processor to execute the instructions to perform operations comprising: storing an indication in connection with a first provider edge router in an intra-virtual private network connectivity database, the indication to define an additional connectivity for the first provider edge router beyond connectivity defined in a virtual private network routing and forwarding table associated with the first provider edge router, the additional connectivity defined in the indication including an identification of a second provider edge router to which the first provider edge router is to be communicatively coupled;receiving a border gateway protocol advertisement from the first provider edge router, the border gateway protocol advertisement including a first border gateway protocol route target attribute included in an export policy of the virtual routing and forwarding table associated with the first provider edge router;generating a copy of the border gateway protocol advertisement;and modifying the first border gateway protocol route target attribute of the copy to correspond to the additional connectivity of the indication stored in the database.
- 7Broadest claimClaim Score 45, average(NHIP)A method, comprising:storing an indication in connection with a first provider edge router in an intra-virtual private network connectivity database, the indication to define an additional connectivity for the first provider edge router beyond connectivity defined in a virtual private network routing and forwarding table associated with the first provider edge router, the additional connectivity defined in the indication including an identification of a second provider edge router to which the first provider edge router is to be communicatively coupled;receiving a border gateway protocol advertisement from the first provider edge router, the first border gateway protocol advertisement including a first border gateway protocol route target attribute included in an export policy of the virtual routing and forwarding table associated with the first provider edge router;generating a copy of the border gateway protocol advertisement;and modifying the first border gateway protocol route target attribute of the copy to identify the additional connectivity of the indication stored in the database.
- 13A tangible machine readable medium not comprising propagating signals and having instructions stored thereon that, when executed, cause a machine to perform operations comprising:storing an indication in connection with a first provider edge router in an intra-virtual private network connectivity database, the indication to define an additional connectivity for the first provider edge router beyond connectivity defined in a virtual private network routing and forwarding table associated with the first provider edge router, the additional connectivity defined in the first indication comprising an identification of a second provider edge router to which the first provider edge router is to be communicatively coupled;receiving a border gateway protocol advertisement from the first provider edge router, the border gateway protocol advertisement including a first border gateway protocol route target attribute included in an export policy of the virtual routing and forwarding table associated with the first provider edge router;generating a copy of the border gateway protocol advertisement;and modifying the first border gateway protocol route target attribute of the copy to correspond to the additional connectivity of the indication stored in the database.
Independent claims3
43 paragraphs in 5 sections, as filed
RELATED APPLICATION
0001This patent arises from a continuation of U.S. patent application Ser. No. 12/262,675, filed on Oct. 31, 2008, now U.S. Pat. No. 8,121,118, which is hereby incorporated herein by reference in its entirety.
FIELD OF THE DISCLOSURE
0002This disclosure relates generally to virtual private networks (VPNs) and, more particularly, to methods and apparatus to dynamically control connectivity within VPNs.
BACKGROUND
0003Enterprise customers are increasingly adopting multiprotocol label switching (MPLS) based VPN services to implement a communication network among their respective customer sites via a service provider's network. Such MPLS-based VPNs provide direct any-to-any reachability among an enterprise's customer sites.
BRIEF DESCRIPTION OF THE DRAWINGS
0004<figref idref="DRAWINGS">FIG. 1</figref> is a schematic illustration of example communication system constructed in accordance with the teachings of this disclosure.
0005<figref idref="DRAWINGS">FIG. 2</figref> illustrates example default intra-VPN connectivity configurations for the example communication system of <figref idref="DRAWINGS">FIG. 1</figref>.
0006<figref idref="DRAWINGS">FIG. 3</figref> illustrates an example manner of implementing a route server for the example communication system of <figref idref="DRAWINGS">FIG. 1</figref>.
0007<figref idref="DRAWINGS">FIG. 4</figref> illustrates an example data structure that may be used to implement an intra-VPN connectivity database for the example route server of <figref idref="DRAWINGS">FIG. 3</figref>.
0008<figref idref="DRAWINGS">FIG. 5</figref> is a flowchart representative of an example process that may be carried out to implement the example route servers of <figref idref="DRAWINGS">FIGS. 1</figref> and/or <b>3</b>.
0009<figref idref="DRAWINGS">FIG. 6</figref> is a schematic illustration of an example processor platform that may be used and/or programmed to carry out the example process of <figref idref="DRAWINGS">FIG. 5</figref> and/or to implement any of all of the methods and apparatus disclosed herein.
DETAILED DESCRIPTION
0010Example methods and apparatus to dynamically control connectivity within virtual private networks (VPNs) are disclosed. A disclosed example route server to control connectivity within a VPN includes a memory to implement an intra-VPN connectivity database, a border gateway protocol (BGP) engine to process BGP advertisements, a network interface to receive a first BGP advertisement from a first provider edge (PE) router associated with the VPN, the first BGP advertisement including a first route target (RT) associated with the first PE router, and an intra-VPN connectivity controller to, in response to the first BGP advertisement, query the database to determine whether the first PE router is to be communicatively coupled to a second PE router of the VPN and when the first and second PE routers of the VPN are to be communicatively coupled, direct the BGP engine to form a second BGP advertisement based on the first BGP advertisement, the second BGP advertisement including a second RT associated with the second PE router.
0011A disclosed example method includes receiving a first BGP advertisement from a first PE router associated with a VPN, the first BGP advertisement including a first RT associated with the first PE router, automatically querying an intra-VPN connectivity database to determine whether the first PE router is to be communicatively coupled to a second PE router of the VPN, forming a second BGP advertisement based on the first BGP advertisement when the first and second PE routers of the VPN are to be communicatively coupled, the second BGP advertisement including a second RT associated with the second PE router, and broadcasting the second BGP advertisement.
0012In the interest of brevity and clarity, throughout the following disclosure references will be made to an example multiprotocol label switching (MPLS) based communication system <b>100</b> of <figref idref="DRAWINGS">FIG. 1</figref>. However, the methods and apparatus described herein to dynamically control connectivity within VPNs are applicable to other types of networks constructed using other technologies, topologies and/or protocols.
0013<figref idref="DRAWINGS">FIG. 1</figref> illustrates the example MPLS-based communication system <b>100</b>. To facilitate communication services between a plurality of customer edge (CE) routers, eight of which are designated at reference numerals <b>105</b>-<b>112</b>, the example communication system <b>100</b> of <figref idref="DRAWINGS">FIG. 1</figref> includes a service-provider network <b>115</b>. While for ease of illustration and discussion, all of the example CE routers <b>105</b>-<b>112</b> are associated with a single VPN, the example communication system <b>100</b> of <figref idref="DRAWINGS">FIG. 1</figref> may facilitate communication services for a plurality of VPNs. Moreover, not all of the VPNs implemented by the example communication system <b>100</b> need include and/or implement the methods and apparatus to dynamically control intra-VPN connectivity.
0014To route and/or transport data between and/or among the example CE routers <b>105</b>-<b>112</b>, the example service-provider network <b>115</b> of <figref idref="DRAWINGS">FIG. 1</figref> includes a plurality of PE routers, four of which are designated at reference numerals <b>120</b>, <b>121</b>, <b>122</b> and <b>123</b>. The example PE routers <b>120</b>-<b>123</b> of <figref idref="DRAWINGS">FIG. 1</figref> are communicatively coupled to each other via any number and/or type(s) of communication paths (not shown) that allow any particular PE router <b>120</b>-<b>123</b> to communicate with at least some, but not necessarily all of, the other PE routers <b>120</b>-<b>123</b>.
0015For each VPN implemented by the service-provider network <b>115</b>, each of the example PE routers <b>120</b>-<b>123</b> of <figref idref="DRAWINGS">FIG. 1</figref> has a corresponding VPN routing and forwarding (VRF) table. In the illustrated example of <figref idref="DRAWINGS">FIG. 1</figref>, the PE router <b>120</b> has a VRF table <b>130</b>, the PE router <b>121</b> has a VRF table <b>131</b>, the PE router <b>122</b> has a VRF table <b>132</b>, and the PE router <b>123</b> has a VRF table <b>133</b>. The example VRF tables <b>130</b>-<b>133</b> of <figref idref="DRAWINGS">FIG. 1</figref> are associated with the VPN communicatively coupling the example CE routers <b>105</b>-<b>112</b>. The example VRF tables <b>130</b>-<b>133</b> are used by the PE routers <b>120</b>-<b>123</b> to route and/or forward a packet received at a particular PE router <b>120</b>-<b>123</b> to and/or toward its final destination. In general, when a packet is received at a PE router <b>120</b>-<b>123</b> from a CE router <b>105</b>-<b>112</b> associated with a particular VPN, the PE router <b>120</b>-<b>123</b> uses the final destination specified and/or identified in the packet to perform a query of the VRF table <b>130</b>-<b>133</b> associated with that VPN. Based on a result of the query, the PE router <b>120</b>-<b>123</b> determines how the packet is to be routed or forwarded within the service provider network <b>110</b>, and/or delivered to a particular CE router <b>105</b>-<b>112</b>.
0016By sending, for example, BGP route advertisements, each of the example PE routers <b>120</b>-<b>123</b> of <figref idref="DRAWINGS">FIG. 1</figref> publishes and/or exports information concerning the CE router(s) <b>105</b>-<b>112</b> that are communicatively coupled to the PE router <b>120</b>-<b>123</b>. Isolation between different VPNs and/or between different devices of a VPN is achieved via RTs, import policies and/or export policies. Specifically, BGP advertisements and/or routes within a BGP advertisement are tagged with an RT value. The RT that is included in a BGP advertisement is defined by the export policy of the PE router <b>120</b>-<b>123</b> that is sending the BGP advertisement. For instance, when the example PE router <b>120</b> of <figref idref="DRAWINGS">FIG. 1</figref> sends a BGP advertisement containing information regarding any of the CE routers <b>105</b>-<b>107</b>, the BGP advertisement includes an RT B, as defined by an export policy <b>135</b> associated with the VRF table <b>130</b>.
0017Based on received BGP route advertisements, the example PE routers <b>120</b>-<b>123</b> of <figref idref="DRAWINGS">FIG. 1</figref> build, compile, update, maintain and/or construct their respective VRF tables <b>130</b>-<b>133</b>. The example PE routers <b>120</b>-<b>123</b> import routes in accordance with their associated import policy. In the illustrated example of <figref idref="DRAWINGS">FIG. 1</figref>, when the example PE router <b>123</b> receives a BGP advertisement tagged with an RT, the PE router <b>123</b> compares the RT contained in the BGP advertisement with its import policy <b>136</b>. If the import policy <b>136</b> specifies that routes associated with that RT are to be imported, the PE router <b>123</b> updates its VRF table <b>133</b>. For example, if the BGP advertisement includes an RT G, the PE router <b>123</b> would import the routes listed in the BGP advertisement. However, BGP advertisements including other RTs would be ignored.
0018By configuring the import and export policies of the example VRF tables <b>130</b>-<b>133</b>, nominal and/or default routes between the example PE routers <b>120</b>-<b>123</b> for the example VPN of <figref idref="DRAWINGS">FIG. 1</figref> can be controlled, as shown in <figref idref="DRAWINGS">FIG. 2</figref>. For example, if the values A, B, C, D, E, F and G of <figref idref="DRAWINGS">FIG. 1</figref> are configured to have the same value, then the example VPN of <figref idref="DRAWINGS">FIG. 1</figref> is configured in the any-to-any topology traditionally utilized within VPNs. If the values A, B, C, D, E, F and G are all different, then no routes between any of PE routers <b>120</b>-<b>123</b> for the example VPN of <figref idref="DRAWINGS">FIG. 1</figref> have been configured and/or enabled. If the values A, C, E, and H have a first value, and the values B, D, F and G have a second value, then the example VPN of <figref idref="DRAWINGS">FIG. 1</figref> is configured in a hub and spoke topology. In particular, the example PE router <b>123</b> would operate as a hub router for the VPN with the other PE routers <b>120</b>-<b>122</b> operating as spoke routers.
0019Returning to <figref idref="DRAWINGS">FIG. 1</figref>, to facilitate sharing of routing information among the example PE routers <b>120</b>-<b>123</b>, the example service provider network <b>110</b> of <figref idref="DRAWINGS">FIG. 1</figref> includes any number of route servers, route reflectors, intelligent route reflectors and/or intelligent route service control points, one of which is designated at reference numeral <b>140</b>. Because not all of the example PE routers <b>120</b>-<b>123</b> are necessarily communicatively coupled in a full mesh topology (for example, when at least one PE router <b>120</b>-<b>123</b> does not have a direct communication path to another PE router <b>120</b>-<b>123</b>), the example route server <b>140</b> of <figref idref="DRAWINGS">FIG. 1</figref> forwards BGP advertisements among and/or to the PE routers <b>120</b>-<b>123</b>. By forwarding each received BGP advertisement, the example route server <b>140</b> enables each of the PE routers <b>120</b>-<b>123</b> to build, compile and/or construct a VRF table <b>130</b>-<b>133</b> that can be used by the PE router <b>120</b>-<b>123</b> to route data from any of its communicatively coupled CE routers <b>105</b>-<b>112</b> to none, some or all of the CE routers <b>105</b>-<b>112</b> communicatively coupled to other PE routers <b>120</b>-<b>123</b>, even if such routing of data requires use of one or more intervening PE routers <b>120</b>-<b>123</b>.
0020To dynamically control communication within the example VPN of <figref idref="DRAWINGS">FIG. 1</figref> without having to reconfigure and/or change import and/or export policies of a VRF table <b>130</b>-<b>133</b>, the example route server <b>140</b> of <figref idref="DRAWINGS">FIG. 1</figref> forms a copy of each BGP advertisement that it receives, modifies the copy of the received BGP advertisement, and sends and/or broadcasts the modified BGP advertisement. For example, when the example PE router <b>120</b> is to be communicatively coupled to the example PE router <b>122</b> for a particular VPN and the example route server <b>140</b> of <figref idref="DRAWINGS">FIG. 1</figref> receives a BGP advertisement <b>150</b> that includes the RT B associated with the export policy <b>135</b> of the VRF table <b>130</b>, the example route server <b>140</b> broadcasts a version <b>151</b> of the BGP advertisement <b>150</b> that includes an RT E associated with an import policy <b>155</b> of the VRF table <b>132</b>. Likewise, when the example route server <b>140</b> receives a BGP advertisement <b>152</b> that includes an RT F associated with an export policy <b>156</b> of the VRF table <b>132</b>, the example route server <b>140</b> broadcasts a version <b>153</b> of the BGP advertisement <b>152</b> that includes an RT A associated an import policy <b>157</b> of the VRF table <b>130</b>. When a particular PE router <b>120</b>-<b>123</b> is not to have additional connectivity within a VPN beyond that defined by the import and/or export policy of the PE router <b>120</b>-<b>123</b>, the route server <b>140</b> forwards the originally received BGP advertisements <b>150</b> and <b>152</b> without making, modifying and/or sending a copy of the received BGP advertisements <b>150</b> and/or <b>152</b>.
0021Intra-VPN connectivity enabled by the example route server <b>140</b> is in addition to any intra-VPN connectivity defined by the import and/or export policies of the VRF tables <b>130</b>-<b>132</b>. For example, if the values A, B, C, D, E, F and G are all different, the route server <b>140</b> is the sole enabler for connectivity within the example VPN of <figref idref="DRAWINGS">FIG. 1</figref>. However, if the values A, C, E, and H have a first value, and the values B, D, F and G have a second value thereby enabling a hub and spoke topology with the PE router <b>123</b> operating as a hub router, the example route server <b>140</b> can be used to dynamically enable additional connectivity between the spoke PE routers <b>120</b>-<b>122</b>.
0022To determine whether PE routers <b>120</b>-<b>123</b> are to have additional connectivity within a VPN beyond that defined by their respective import and export policies, the example route server <b>140</b> of <figref idref="DRAWINGS">FIG. 1</figref> queries an intra-VPN connectivity database <b>305</b> (<figref idref="DRAWINGS">FIG. 3</figref>). As described below in connection with <figref idref="DRAWINGS">FIGS. 3 and 4</figref>, a user and/or computer <b>310</b> can dynamically and/or selectively configure connectivity within a VPN by configuring the intra-VPN connectivity database <b>305</b>. An example manner of implementing the example route server <b>140</b> of <figref idref="DRAWINGS">FIG. 1</figref> is described below in connection with <figref idref="DRAWINGS">FIG. 3</figref>.
0023While an example communication system has been illustrated in <figref idref="DRAWINGS">FIG. 1</figref>, one or more of the interfaces, data structures, elements, processes and/or devices illustrated in <figref idref="DRAWINGS">FIG. 1</figref> may be combined, divided, re-arranged, omitted, eliminated and/or implemented in any other way. Further, the example PE routers <b>120</b>-<b>123</b> and/or the example route server <b>140</b> of <figref idref="DRAWINGS">FIG. 1</figref> may be implemented by hardware, software, firmware and/or any combination of hardware, software and/or firmware. Thus, for example, any of the example PE routers <b>120</b>-<b>123</b> and/or the example route server <b>140</b> may be implemented by one or more circuit(s), programmable processor(s), application specific integrated circuit(s) (ASIC(s)), programmable logic device(s) (PLD(s)) and/or field programmable logic device(s) (FPLD(s)), etc. Further still, a communication system may include interfaces, data structures, elements, processes and/or devices instead of, or in addition to, those illustrated in <figref idref="DRAWINGS">FIG. 1</figref> and/or may include more than one of any or all of the illustrated interfaces, data structures, elements, processes and/or devices.
0024<figref idref="DRAWINGS">FIG. 3</figref> illustrates an example manner of implementing the example route server <b>140</b> of <figref idref="DRAWINGS">FIG. 1</figref>. To implement one or more interfaces to the example PE routers <b>120</b>-<b>123</b>, the example route server <b>140</b> of <figref idref="DRAWINGS">FIG. 3</figref> includes any number and/or type(s) of network interfaces, one of which is designated at reference numeral <b>315</b>.
0025To send, receive and process BGP route advertisements, the example route server <b>140</b> of <figref idref="DRAWINGS">FIG. 3</figref> includes a multi-protocol BGP engine <b>320</b>. When a BGP route advertisement is received from a PE router <b>120</b>-<b>123</b> via the example network interface <b>315</b>, the example multi-protocol BGP engine <b>320</b> of <figref idref="DRAWINGS">FIG. 3</figref> forwards the received BGP route advertisement to the other PE routers <b>120</b>-<b>123</b>. The example multi-protocol BGP engine <b>320</b> also queries an intra-VPN connectivity controller <b>325</b> to determine whether one or more modified copies of the received BGP router advertisement are to be broadcast.
0026To control connectivity within a VPN, the example route server <b>140</b> of <figref idref="DRAWINGS">FIG. 3</figref> includes the example intra-VPN connectivity controller <b>325</b>. When queried by the example multi-protocol BGP engine <b>320</b>, the example intra-VPN connectivity controller <b>325</b> of <figref idref="DRAWINGS">FIG. 3</figref> queries the example intra-VPN connectivity database <b>305</b> to determine whether BGP advertisements associated with a first RT are to be re-broadcast with one or more additional RT. When intra-VPN connectivity beyond that defined by import and/or export policies is to be enabled for a particular RT, the example intra-VPN connectivity controller <b>325</b> returns to the multi-protocol BGP engine <b>320</b> the one or more additional RTs with which the received BGP route advertisement is to be re-broadcast.
0027In response to the one more additional RTs, the example multi-protocol BGP engine <b>320</b> of <figref idref="DRAWINGS">FIG. 3</figref> creates one or more corresponding copies of the received BGP advertisement, modifies the original RT to correspond with a respective one of the one or more additional RTs, and broadcasts the modified copy(-ies) of the received BGP advertisement.
0028Intra-VPN connectivity configuration information may be stored in the example intra-VPN connectivity database <b>305</b> using any number and/or type(s) of data structures. An example data structure that may be used to implement the example shared resource control access database <b>305</b> of <figref idref="DRAWINGS">FIG. 3</figref> is described below in connection with <figref idref="DRAWINGS">FIG. 4</figref>. The example intra-VPN connectivity database <b>305</b> may be stored using any number and/or type(s) of memory(-ies), memory device(s) and/or storage device(s).
0029To allow the user and/or computer <b>310</b> to configure intra-VPN connectivity for a VPN, the example route server <b>140</b> of <figref idref="DRAWINGS">FIG. 3</figref> includes any number and/or type(s) of user interface modules, one of which is designated at reference numeral <b>330</b>. The example user <b>310</b> of <figref idref="DRAWINGS">FIG. 3</figref> may be associated with a particular VPN, and/or be associated with an operator of the service-provider network <b>115</b>. The example user interface module <b>330</b> of <figref idref="DRAWINGS">FIG. 3</figref> enables the user <b>310</b> to interact with the example intra-VPN connectivity controller <b>325</b> to update the database <b>305</b> to configure connectivity within a VPN. In some examples, intra-VPN connectivity can be configured differently for different periods of time, temporarily configured with an expiration time, and/or automatically re-configured in response to a triggering event. For instance, during business hours there may be full connectivity within a VPN, with the VPN reverting to a nominal hub-and-spoke topology during non-business hours. Additionally or alternatively, if a virus and/or security anomaly is detected, connectivity within a VPN may be restricted and/or blocked to reduce the likelihood of damage. Example user interface modules <b>330</b> include, but are not limited to, a web-based interface, a voice activated response system and/or an application programming interface accessible to another computer system <b>310</b>.
0030While an example route server <b>140</b> has been illustrated in <figref idref="DRAWINGS">FIG. 3</figref>, one or more of the interfaces, data structures, elements, processes and/or devices illustrated in <figref idref="DRAWINGS">FIG. 3</figref> may be combined, divided, re-arranged, omitted, eliminated and/or implemented in any other way. Further, the example intra-VPN connectivity database <b>305</b>, the example network interface <b>315</b>, the example multi-protocol BGP engine <b>320</b>, the example intra-VPN connectivity controller <b>325</b>, the example user interface module <b>330</b>, and/or, more generally, the example route server <b>140</b> of <figref idref="DRAWINGS">FIG. 3</figref> may be implemented by hardware, software, firmware and/or any combination of hardware, software and/or firmware. Thus, for example, any or the example intra-VPN connectivity database <b>305</b>, the example network interface <b>315</b>, the example multi-protocol BGP engine <b>320</b>, the example intra-VPN connectivity controller <b>325</b>, the example user interface module <b>330</b>, and/or, more generally, the example route server <b>140</b> may be implemented by one or more circuit(s), programmable processor(s), ASIC(s), PLD(s) and/or FPLD(s), etc. Further still, a route server may include interfaces, data structures, elements, processes and/or devices instead of, or in addition to, those illustrated in <figref idref="DRAWINGS">FIG. 3</figref> and/or may include more than one of any or all of the illustrated interfaces, data structures, elements, processes and/or devices.
0031<figref idref="DRAWINGS">FIG. 4</figref> illustrates an example data structure that may be used to implement the example intra-VPN connectivity database <b>305</b> of <figref idref="DRAWINGS">FIG. 3</figref>. The example data structure of <figref idref="DRAWINGS">FIG. 4</figref> includes a plurality of entries for respective ones of pairs of RTs, one of which is designated at reference numeral <b>410</b>. Each of the example entries <b>410</b> is associated with a particular combination of RTs. For instance, the example entry <b>410</b> is associated with a combination of RT F and RT G.
0032To identify whether communication between the VRFs <b>130</b>-<b>133</b> associated with a particular combination of RTs is currently enabled, each of the example entries <b>410</b> contains one or more values, flags, rules, criteria and/or strings that represent whether the example route server <b>140</b> is to cross-communicate BGP advertisements between the RTs associated with the entry <b>410</b>. Example entries <b>410</b> include, but are not limited to, a flag that indicates that connectivity between the RTs is unconditionally enabled, a time of day range that specifies when connectivity is enabled, a condition when connectivity is enabled, and/or a condition when connectivity is disabled. In some examples, the example entries <b>410</b> of <figref idref="DRAWINGS">FIG. 4</figref> each contain a simple flag to indicate whether the example route server <b>140</b> is to cross-communicate BGP advertisements between the RTs associated with the entry <b>410</b>. In such examples, the example user and/or computer <b>310</b> (<figref idref="DRAWINGS">FIG. 3</figref>) is responsible for configuring the example intra-VPN connectivity database <b>305</b> in response to one or more of conditions, time of day, day of week and/or triggering events.
0033While an example data structure that may be used to implement the example intra-VPN connectivity database <b>305</b> of <figref idref="DRAWINGS">FIG. 3</figref> is illustrated in <figref idref="DRAWINGS">FIG. 4</figref>, the example data structure of <figref idref="DRAWINGS">FIG. 4</figref> may be implemented using any number and/or type(s) of other and/or additional entries, fields and/or data. Further, the entries, fields and/or data illustrated in <figref idref="DRAWINGS">FIG. 4</figref> may be combined, divided, re-arranged, eliminated and/or implemented in any way. Further still, the example data structures may include entries, fields and/or data in addition to, or instead of, those illustrated in <figref idref="DRAWINGS">FIG. 4</figref>, and/or may include more than one of any or all of the illustrated entries, fields and/or data. Moreover, the example data structure <b>305</b> of <figref idref="DRAWINGS">FIG. 4</figref> may be queried using any additional and/or alternative methods.
0034<figref idref="DRAWINGS">FIG. 5</figref> illustrates a flowchart representative of an example process that may be carried out to implement any of the example route servers <b>140</b> of <figref idref="DRAWINGS">FIGS. 1</figref> and/or <b>3</b>. The example process of <figref idref="DRAWINGS">FIG. 5</figref> may be carried out by a processor, a controller and/or any other suitable processing device. For example, the example process of <figref idref="DRAWINGS">FIG. 5</figref> may be embodied in coded instructions stored on any tangible computer-readable medium such as a flash memory, a compact disc (CD), a digital versatile disc (DVD), a floppy disk, a read-only memory (ROM), a random-access memory (RAM), a programmable ROM (PROM), an electronically-programmable ROM (EPROM), and/or an electronically-erasable PROM (EEPROM), an optical storage disk, an optical storage device, magnetic storage disk, a magnetic storage device, and/or any other medium which can be used to carry or store program code and/or instructions in the form of machine-accessible instructions or data structures, and which can be accessed by a processor, a general-purpose or special-purpose computer, or other machine with a processor (e.g., the example processor platform P<b>100</b> discussed below in connection with <figref idref="DRAWINGS">FIG. 6</figref>). Combinations of the above are also included within the scope of computer-readable media. Machine-accessible instructions comprise, for example, instructions and/or data that cause a processor, a general-purpose computer, special-purpose computer, or a special-purpose processing machine to implement one or more particular processes. Alternatively, some or all of the example process of <figref idref="DRAWINGS">FIG. 5</figref> may be implemented using any combination(s) of ASIC(s), PLD(s), FPLD(s), discrete logic, hardware, firmware, etc. Also, some or all of the example process of <figref idref="DRAWINGS">FIG. 5</figref> may instead be implemented manually or as any combination of any of the foregoing techniques, for example, any combination of firmware, software, discrete logic and/or hardware. Further, many other methods of implementing the example operations of <figref idref="DRAWINGS">FIG. 5</figref> may be employed. For example, the order of execution of the blocks may be changed, and/or one or more of the blocks described may be changed, eliminated, sub-divided, or combined. Additionally, any or all of the example process of <figref idref="DRAWINGS">FIG. 5</figref> may be carried out sequentially and/or carried out in parallel by, for example, separate processing threads, processors, devices, discrete logic, circuits, etc.
0035The example process of <figref idref="DRAWINGS">FIG. 5</figref> begins with the example user interface module <b>330</b> of <figref idref="DRAWINGS">FIG. 3</figref> determining whether updated intra-VPN connectivity configuration information has been received (block <b>505</b>). If updated intra-VPN connectivity configuration information has been received (block <b>505</b>), the example intra-VPN connectivity controller <b>325</b> makes corresponding updates to the example intra-VPN connectivity database <b>305</b> (block <b>510</b>). Control then returns to block <b>505</b>.
0036If updated intra-VPN connectivity configuration information was not received (block <b>505</b>), the example multi-protocol BGP engine <b>320</b> of <figref idref="DRAWINGS">FIG. 3</figref> determines whether a BGP advertisement was received via the example network interface <b>315</b> (block <b>515</b>). If a BGP advertisement was not received (block <b>515</b>), control returns to block <b>505</b>.
0037If a BGP advertisement was received (block <b>515</b>), the multi-protocol BGP engine <b>320</b> broadcasts the received BGP advertisement (block <b>520</b>). The multi-protocol BGP engine <b>320</b> queries the intra-VPN connectivity controller <b>325</b> to determine whether modified copies of the received BGP advertisement are to be broadcast (block <b>525</b>). If the intra-VPN connectivity controller <b>325</b> determines that no modified copies of the received BGP advertisement are to be broadcast (block <b>525</b>), control returns to block <b>505</b>.
0038If based on a query of the example intra-VPN connectivity database <b>305</b>, the intra-VPN connectivity controller <b>325</b> returns one or more RTs (block <b>525</b>), the multi-protocol BGP engine <b>320</b> creates one or more corresponding copies of the received BGP advertisement (block <b>530</b>), modifies the RT of the copy(-ies) with respective ones of the returned RT(s) (block <b>535</b>), and broadcasts the modified BGP advertisement(s) (block <b>540</b>). Control then returns to block <b>505</b>.
0039<figref idref="DRAWINGS">FIG. 6</figref> is a schematic diagram of an example processor platform P<b>100</b> that may be used and/or programmed to implement any of the example route servers <b>140</b> of <figref idref="DRAWINGS">FIGS. 1</figref> and/or <b>2</b>. For example, the processor platform P<b>100</b> can be implemented by one or more general-purpose processors, processor cores, microcontrollers, etc.
0040The processor platform P<b>100</b> of the example of <figref idref="DRAWINGS">FIG. 6</figref> includes at least one general purpose programmable processor P<b>105</b>. The processor P<b>105</b> executes coded instructions P<b>110</b> and/or P<b>112</b> present in main memory of the processor P<b>105</b> (e.g., within a RAM P<b>115</b> and/or a ROM P<b>120</b>). The processor P<b>105</b> may be any type of processing unit, such as a processor core, a processor and/or a microcontroller. The processor P<b>105</b> may execute, among other things, the example process of <figref idref="DRAWINGS">FIG. 5</figref> to implement the example methods and apparatus described herein.
0041The processor P<b>105</b> is in communication with the main memory (including a ROM P<b>120</b> and/or the RAM P<b>115</b>) via a bus P<b>125</b>. The RAM P<b>115</b> may be implemented by DRAM, SDRAM, and/or any other type of RAM device, and ROM may be implemented by flash memory and/or any other desired type of memory device. Access to the memory P<b>115</b> and the memory P<b>120</b> may be controlled by a memory controller (not shown). One or both of the example memories P<b>115</b> and P<b>120</b> may be used to implement the example intra-VPN connectivity database <b>305</b> of <figref idref="DRAWINGS">FIG. 3</figref>.
0042The processor platform P<b>100</b> also includes an interface circuit P<b>130</b>. The interface circuit P<b>130</b> may be implemented by any type of interface standard, such as an external memory interface, serial port, general-purpose input/output, etc. One or more input devices P<b>135</b> and one or more output devices P<b>140</b> are connected to the interface circuit P<b>130</b>. The input devices P<b>135</b> and/or output devices P<b>140</b> may be used to, for example, implement the network interface <b>315</b> of <figref idref="DRAWINGS">FIG. 3</figref>.
0043Although certain example methods, apparatus and articles of manufacture have been described herein, the scope of coverage of this patent is not limited thereto. On the contrary, this patent covers all methods, apparatus and articles of manufacture fairly falling within the scope of the appended claims either literally or under the doctrine of equivalents.
Contents5
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US10178025B2 | Cited by | United States of America | Search report |
| US9401844B2 | Cited by | United States of America | Applicant |
| US11115323B2 | Cited by | United States of America | Applicant |
| US2017118112A1 | Cited by | United States of America | Pre-grant |
| US2002181477A1 | Cites | United States of America | Applicant |
| US2003016672A1 | Cites | United States of America | Search report |
| US2003188001A1 | Cites | United States of America | Applicant |
| US2004148439A1 | Cites | United States of America | Applicant |
| US2005066053A1 | Cites | United States of America | Applicant |
| US2006165087A1 | Cites | United States of America | Applicant |
| US2006168279A1 | Cites | United States of America | Applicant |
| US2006168321A1 | Cites | United States of America | Applicant |
| US2006251088A1 | Cites | United States of America | Applicant |
| US2007133577A1 | Cites | United States of America | Applicant |
| US2007140250A1 | Cites | United States of America | Applicant |
| US2007140251A1 | Cites | United States of America | Applicant |
| US2007195800A1 | Cites | United States of America | Applicant |
| US2007217419A1 | Cites | United States of America | Applicant |
| US2007280241A1 | Cites | United States of America | Applicant |
| US2008002697A1 | Cites | United States of America | Applicant |
| US2008049752A1 | Cites | United States of America | Applicant |
| US2008080517A1 | Cites | United States of America | Applicant |
| US2008170578A1 | Cites | United States of America | Search report |
| US2010111093A1 | Cites | United States of America | Applicant |
| US2010115604A1 | Cites | United States of America | Applicant |
| US5623601A | Cites | United States of America | Applicant |
| US6079020A | Cites | United States of America | Applicant |
| US6205488B1 | Cites | United States of America | Applicant |
| US6636898B1 | Cites | United States of America | Applicant |
| US6781982B1 | Cites | United States of America | Applicant |
| US7072346B2 | Cites | United States of America | Applicant |
| US7075933B2 | Cites | United States of America | Applicant |
| US7131141B1 | Cites | United States of America | Applicant |
| US7185106B1 | Cites | United States of America | Applicant |
| US7221675B2 | Cites | United States of America | Applicant |
| US7225270B2 | Cites | United States of America | Applicant |
| US7340519B1 | Cites | United States of America | Applicant |
| US7366188B2 | Cites | United States of America | Applicant |
| US7388844B1 | Cites | United States of America | Applicant |
| US7400611B2 | Cites | United States of America | Applicant |
| US7564802B2 | Cites | United States of America | Search report |
| US7616574B2 | Cites | United States of America | Applicant |
| US7751405B1 | Cites | United States of America | Search report |
| US7870604B1 | Cites | United States of America | Applicant |
| US7912856B2 | Cites | United States of America | Applicant |
| US7921686B2 | Cites | United States of America | Applicant |
| US8027347B2 | Cites | United States of America | Applicant |
| US8064440B2 | Cites | United States of America | Applicant |
| US8117325B1 | Cites | United States of America | Applicant |
| US8117338B2 | Cites | United States of America | Applicant |
| US8121118B2 | Cites | United States of America | Applicant |
| US8549616B2 | Cites | United States of America | Applicant |
| US20020181477A1 | Cites | United States of America | Applicant |
| US20030016672A1 | Cites | United States of America | Search report |
| US20030188001A1 | Cites | United States of America | Applicant |
| US20040148439A1 | Cites | United States of America | Applicant |
| US20050066053A1 | Cites | United States of America | Applicant |
| US20060165087A1 | Cites | United States of America | Applicant |
| US20060168279A1 | Cites | United States of America | Applicant |
| US20060168321A1 | Cites | United States of America | Applicant |
| US20060251088A1 | Cites | United States of America | Applicant |
| US20070133577A1 | Cites | United States of America | Applicant |
| US20070140250A1 | Cites | United States of America | Applicant |
| US20070140251A1 | Cites | United States of America | Applicant |
| US20070195800A1 | Cites | United States of America | Applicant |
| US20070217419A1 | Cites | United States of America | Applicant |
| US20070280241A1 | Cites | United States of America | Applicant |
| US20080002697A1 | Cites | United States of America | Applicant |
| US20080049752A1 | Cites | United States of America | Applicant |
| US20080080517A1 | Cites | United States of America | Applicant |
| US20080170578A1 | Cites | United States of America | Search report |
| US20100111093A1 | Cites | United States of America | Applicant |
| US20100115604A1 | Cites | United States of America | Applicant |
| United States Patent and Trademark Office, Notice of Allowance and Fee(s) Due, issued for U.S. Appl. No. 121262,675, mailed on Oct. 17, 2011, 16 pages. | Non-patent | – | Applicant |
| United States Patent and Trademark Office, Non-Final Rejection, issued for U.S. Appl. No. 12/262,675, mailed on Apr. 15, 2011, 19 pages. | Non-patent | – | Applicant |
| United States Patent and Trademark Office, Final Rejection, issued for U.S. Appl. No. 12/262,675, mailed on Oct. 4, 2010, 21 pages. | Non-patent | – | Applicant |
| United States Patent and Trademark Office, Non-Final Rejection, issued for U.S. Appl. No. 12/262,675, mailed on May 11, 2010, 12 pages. | Non-patent | – | Applicant |
| Rosen, et al., “BGP/MPLS IP Virtual Private Networks (VPNs),” Network Working Group, Request for Comments: 4364, The Internet Society, Feb. 2006, 47 pages. | Non-patent | – | Applicant |
| Van Der Merwe, et al., “Dynamic Connectivity Management with an Intelligent Route Service Control Point,” AT&T Labs, Proceedings of the 2006 SIGCOMM Workshop on Internet Network Management, held on Sep. 11-15, 2006, 6 pages. | Non-patent | – | Applicant |
| Van Der Merwe, et al., PowerPoint presentation of “Dynamic Connectivity Management with an Intelligent Route Service Control Point,” AT&T Labs, Proceedings of the 2006 SIGCOMM Workshop on Internet Network Management, held on Sep. 11-15, 2006, 14 pages. | Non-patent | – | Applicant |
| United States Patent and Trademark Office, Final Rejection, issued for U.S. Appl. No. 12/262,615, mailed on Mar. 13, 2012, 12 pages. | Non-patent | – | Applicant |
| United States Patent and Trademark Office, Office action, issued for U.S. Appl. No. 12/262,615, mailed on Oct. 4, 2012, 12 pages. | Non-patent | – | Applicant |
| Cisco: IPv6 over MPLS Cisco IPv6 Provider Edge Router (6PE) Cisco IPv6 VPN Provider Edge Router (6VPE); 2006. | Non-patent | – | Applicant |
| The United States Patent and Trademark Office, “Notice of Allowance,” issued in connection with U.S. Appl. No. 12/262,615 on Jun. 3, 2013. | Non-patent | – | Applicant |
| The United States Patent and Trademark Office, “Notice of Allowance,” issued in connection with U.S. Appl. No. 12/262,615 on Feb. 20, 2013. | Non-patent | – | Applicant |
| The United States Patent and Trademark Office, “Advisory action,” issued in connection with U.S. Appl. No. 12/262,615 on Dec. 14, 2012. | Non-patent | – | Applicant |
| United States Patent and Trademark Office, Notice of Allowance and Fee(s) Due, issued for U.S. Appl. No. 121262,675, mailed on Oct. 17, 2011, 16 pages. | Non-patent | – | Applicant |
| United States Patent and Trademark Office, Non-Final Rejection, issued for U.S. Appl. No. 12/262,675, mailed on Apr. 15, 2011, 19 pages. | Non-patent | – | Applicant |
| United States Patent and Trademark Office, Final Rejection, issued for U.S. Appl. No. 12/262,675, mailed on Oct. 4, 2010, 21 pages. | Non-patent | – | Applicant |
| United States Patent and Trademark Office, Non-Final Rejection, issued for U.S. Appl. No. 12/262,675, mailed on May 11, 2010, 12 pages. | Non-patent | – | Applicant |
| Rosen, et al., "BGP/MPLS IP Virtual Private Networks (VPNs)," Network Working Group, Request for Comments: 4364, The Internet Society, Feb. 2006, 47 pages. | Non-patent | – | Applicant |
| Van Der Merwe, et al., "Dynamic Connectivity Management with an Intelligent Route Service Control Point," AT&T Labs, Proceedings of the 2006 SIGCOMM Workshop on Internet Network Management, held on Sep. 11-15, 2006, 6 pages. | Non-patent | – | Applicant |
| Van Der Merwe, et al., PowerPoint presentation of "Dynamic Connectivity Management with an Intelligent Route Service Control Point," AT&T Labs, Proceedings of the 2006 SIGCOMM Workshop on Internet Network Management, held on Sep. 11-15, 2006, 14 pages. | Non-patent | – | Applicant |
| United States Patent and Trademark Office, Final Rejection, issued for U.S. Appl. No. 12/262,615, mailed on Mar. 13, 2012, 12 pages. | Non-patent | – | Applicant |
| United States Patent and Trademark Office, Office action, issued for U.S. Appl. No. 12/262,615, mailed on Oct. 4, 2012, 12 pages. | Non-patent | – | Applicant |
| Cisco: IPv6 over MPLS Cisco IPv6 Provider Edge Router (6PE) Cisco IPv6 VPN Provider Edge Router (6VPE); 2006. | Non-patent | – | Applicant |
| The United States Patent and Trademark Office, "Notice of Allowance," issued in connection with U.S. Appl. No. 12/262,615 on Jun. 3, 2013. | Non-patent | – | Applicant |
| The United States Patent and Trademark Office, "Notice of Allowance," issued in connection with U.S. Appl. No. 12/262,615 on Feb. 20, 2013. | Non-patent | – | Applicant |
| The United States Patent and Trademark Office, "Advisory action," issued in connection with U.S. Appl. No. 12/262,615 on Dec. 14, 2012. | Non-patent | – | Applicant |
8 members in 1 office
Priority claims1
| Document | Office | Kind | Date |
|---|---|---|---|
| 26267508 | United States of America | A |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| US2010111093A1 | United States of America | A1 | |
| US8121118B2 | United States of America | B2 | |
| US2012113991A1 | United States of America | A1 | |
| US8929367B2This record | United States of America | B2 | |
| US2015078203A1 | United States of America | A1 | |
| US9137109B2 | United States of America | B2 | |
| US2015365287A1 | United States of America | A1 | |
| US9401844B2 | United States of America | B2 |
47 transactions on the USPTO file
Allowed after 1 non-final rejection.
- Non-final rejections
- 1
- Final rejections
- 0
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Maintenance Fee Reminder MailedREM. | REM. | |
| Payment of Maintenance Fee, 8th Year, Large EntityM1552 | M1552 | |
| Payment of Maintenance Fee, 4th Year, Large EntityM1551 | M1551 | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Interview Summary - Examiner Initiated - TelephonicEXET | EXET | |
| Interview Summary - Examiner InitiatedEXIE | EXIE | |
| Reasons for AllowanceEX.R | EX.R | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Mail Interview Summary - Applicant Initiated - TelephonicMEXAT | MEXAT | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Response after Non-Final ActionA... | A... | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Interview Summary- Applicant InitiatedEXIA | EXIA | |
| Interview Summary - Applicant Initiated - TelephonicEXAT | EXAT | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Transfer Inquiry to GAUTI1050 | TI1050 | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Application Is Now CompleteCOMP | COMP | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Cleared by OIPE CSRL194 | L194 | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Applicants have given acceptable permission for participating foreignAPPERMS | APPERMS | |
| Initial Exam Team nnIEXX | IEXX |
5 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Maintenance fee paymentMAFP | MAFP | |
| Maintenance fee paymentMAFP | MAFP | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| Fee payment procedurePAYOR NUMBER ASSIGNED (ORIGINAL EVENT CODE: ASPN); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| AssignmentAS | AS |
Numbers
- Publication
- 8929367
- Application
- 13349305
Titles
- English
- Methods and apparatus to dynamically control connectivity within virtual private networks
Patent term adjustment
- A delay
- +427 daysthe office missed an examination deadline
- Net adjustment
- 427 days
Classification
- CPC, 8
- H04L12/66
- H04L12/4641
- H04L45/02
- H04L45/033
- H04L65/611
- H04L12/18
- H04L41/0816
- H04L45/50
- IPC, 7
- H04L12 28
- H04L12 66
- H04L12 46
- H04L12 751
- H04L45 02
- H04L45 033
- H04L45 50